SP upgrade 2.3.1 to 2.4.3: disable signature validation of xml metadata?
Jacob Lundberg
jacob at collegenet.com
Mon Jun 17 16:49:16 EDT 2013
Hi Scott,
On Sun, 2013-06-16 at 17:41 +0000, Cantor, Scott wrote:
> I probably don't need to explain the vulnerability you're creating there.
Believe me, I wish we were in a position to dictate this kind of thing
but the complexity of setting up a Shibboleth IdP is already way too
much for some of our clients as it is. I'm not sure exactly how some of
them wind up with unsigned metadata. I'd guess the ones with invalid
signatures just don't know how to sign it after they've updated it...
On Sun, 2013-06-16 at 17:56 +0000, Cantor, Scott wrote:
> > that specific XML is nonsensical/invalid for the standard metadata plugin.
Ok. I can confirm removing the TrustEngine resolves the problem. I've
scoured the documentation some more and I can't find an explanation of
how to configure the list of SSL certificates which are checked for
transport validation of XML metadata loads. I assume some CA list is
checked by default? Would that be whatever the default list is for
libcurl? Is it configurable?
Thanks again for the help,
-Jacob
--
Jacob Lundberg
Director, IT Services
jacob at collegenet.com
503.290.0100 (voice)
503.973.5252 (fax)
503.901.8343 (cell)
More information about the users
mailing list